The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
6
labsDifficulty
Category
ApprenticeCSRF
Changing an email with a single GET
Make a logged-in victim's browser send a state-changing request.
10 pts · 20 minStart →
PractitionerCSRF
A JSON endpoint that accepts form content-type
Make a logged-in victim's browser send a state-changing request.
25 pts · 45 minStart →
PractitionerCSRF
The form with no anti-forgery token
Make a logged-in victim's browser send a state-changing request.
25 pts · 45 minStart →
ExpertCSRF
Defeating a predictable token
Make a logged-in victim's browser send a state-changing request.
50 pts · 90 minStart →
ExpertCSRF
SameSite is not set, and it matters
Make a logged-in victim's browser send a state-changing request.
50 pts · 90 minStart →
MasterCSRF
Login CSRF into an attacker's account
Make a logged-in victim's browser send a state-changing request.
100 pts · 180 minStart →